Government access requests sit at the heart of every transfer impact assessment, because the central question is whether public authorities in the destination country could obtain the data in ways that go beyond what is necessary and proportionate. The law on the books tells part of the story, but the importer’s experience, its contractual commitments and its readiness to respond tell the rest.
This guide explains how to assess government access requests within a TIA, what to ask importers, which contract clauses to seek, how to use transparency reports and what to do if a request is actually received. It is general information, not legal advice, and you should take counsel for the specific destination.
Why government access requests decide many assessments
A TIA does not ask whether a country has surveillance laws in general. It asks whether the specific data you transfer, in the specific way you transfer it, could be reached by authorities in ways that are not limited to what is necessary and proportionate, and whether individuals would have effective redress. Government access requests are the practical test of that question.
The EDPB says that exporters can consider the importer’s practical experience of such requests, as well as the legal framework, when assessing the transfer. See EDPB Recommendations 01/2020 on supplementary measures for the framework. Your assessment should therefore combine legal analysis with facts from the importer.
Understand what powers exist for government access requests
Start with the law. Identify the powers that authorities may use to compel disclosure: national security, law enforcement, tax and regulatory powers. For each, ask who can issue the request, what oversight applies, what limits exist and what remedies are available to affected people.
Take legal advice for higher-risk destinations, and record the sources and date. The analysis mirrors our guide to third-country laws in a TIA. Keep in mind that a law that appears broad may rarely be used against your type of data, and one that appears narrow may be applied broadly, so practice matters as much as text.
Ask the importer about its experience
Send the importer a structured questionnaire. Ask whether it has received government access requests for data like yours, how many, from whom and how it responded. Many importers cannot give numbers because of legal restrictions, but they can describe their approach and confirm whether they have ever disclosed data of the kind you transfer.
Ask for their policy for handling requests: who reviews them, what grounds they use to challenge, how they minimise disclosure and how they record them. A well-run provider will have a documented process and a legal team that reviews each request. Vague answers deserve follow-up.
| Question for the importer | Why it matters | Good answer |
|---|---|---|
| Have you received requests for data of the type we send? | Shows practical exposure | Clear, specific answer, with numbers if permitted |
| How do you assess and challenge requests? | Shows willingness to resist overreach | Written policy, legal review, challenge where grounds exist |
| Will you notify us? | Lets you react or take action | Yes, before disclosure where the law permits |
| Do you publish transparency reports? | Gives independent evidence | Regular, detailed reports |
| What data would you disclose? | Tests effect of encryption and minimisation | Only what is legally required, minimum possible |
- How many requests have you received in the past few years?
- What did you disclose and on what legal basis?
- How do you review and challenge requests?
- Will you notify us, and when?
Use transparency reports
Many large providers publish transparency reports that give figures on government requests, sometimes by country and by request type. These provide independent evidence of how often requests occur and how often they succeed. Use them as one input, but recognise their limits: they may be aggregated, delayed or restricted by law.
Compare the report with your own data profile. If the provider reports many requests for content data from a country, and you send content data there, the risk is higher. If reports show no requests for enterprise data like yours, that supports a lower risk assessment, though it does not guarantee the future.
Free transfer impact assessment
Can this transfer of personal data go ahead?
Check whether the transfer needs a TIA, map it, assess the laws and practice of the destination, rate the risks from 27 transfer scenarios and choose supplementary measures. Covers the EU SCCs and the UK IDTA and Addendum, free.
Contract commitments to seek
Contracts cannot override foreign law, but they can improve the outcome. Seek commitments to notify you of requests where legally allowed, to review each request for legality, to challenge those that appear unlawful, to disclose the minimum data and to keep records. The EU standard contractual clauses contain some of these obligations, and you can add more.
Add audit or information rights so you can verify compliance, and clear termination and data return rights if the importer can no longer comply. Our guides to TIAs for cloud services and TIAs for sub-processors show where these clauses matter most.
Technical measures reduce what can be disclosed
If the importer cannot read the data, government access requests deliver little. Encryption with keys held by you, pseudonymisation and data minimisation reduce the value of any disclosure. Ask what the importer could provide if compelled: only ciphertext, or full plaintext?
Consider the metadata too. Even if content is protected, information about who communicates with whom can be sensitive. See encryption as a supplementary measure and supplementary measures for data transfers for how to combine controls.
Prepare a playbook for government access requests
Plan what you will do if the importer tells you a request has arrived. Define who receives the notice, who assesses the legal position, whether you will object or seek protective orders, how you will inform affected people if allowed and how you will decide on suspending the transfer.
Write the steps down and test them in a short exercise. A playbook that names people and timeframes is far more useful than a generic statement. Include escalation to senior management, and record every request and decision in a log.
Record the reasoning and review it
Your TIA should record the legal analysis, the importer’s answers, the transparency data, the contract terms and the measures, together with your conclusion. Explain why you consider the risk acceptable or how you reduced it. Include the date and the sources.
Review the analysis on a schedule and whenever a request occurs, the law changes or the importer’s practice changes. Our page on TIA review and monitoring explains the process, and the transfer impact assessment example shows a completed record.
Common mistakes with government access requests
Frequent errors include ignoring practical experience and relying only on the text of the law, accepting a supplier’s general statement that it “never discloses data”, failing to ask about notification, forgetting metadata, treating contract clauses as a full solution and not planning what to do when a request arrives. Another is failing to update the assessment after a request.
Avoid these by asking specific questions, requesting evidence, combining technical and contractual measures and keeping a response playbook.
Working with suppliers on an ongoing basis
Build the questions into onboarding and renewal so you get regular updates rather than a one-off answer. Ask suppliers to notify you of changes in their legal exposure, such as new operations in another country or a change of ownership. Keep a contact for legal questions and a channel for urgent notifications. Suppliers that engage openly with these questions are usually the lower-risk choices, and those that resist deserve closer scrutiny.
A short worked example
A company plans to use a cloud collaboration tool hosted in a third country. It reviews the destination’s access laws with counsel, sends the provider a questionnaire and reads its transparency reports. The provider states that it reviews and challenges requests, notifies customers where allowed and has never disclosed enterprise customer content of the kind the company will store.
The company adds contract clauses on notification and challenge, keeps encryption keys in its own region for the most sensitive folders and drafts a short response playbook. The TIA records all of this, and the risk is accepted with a twelve-month review date.
Structuring the assessment
If you want the legal analysis, importer questionnaire, measures and review log in one place, the Transfer Impact Assessment Report and Workbook provides a structured report and workbook for transfer impact assessments. Whatever the format, assessing government access requests properly means combining law, evidence and preparation, and recording your reasoning so it can be reviewed.
Government access requests in a TIA FAQ
Why do government access requests matter in a TIA?
Because the assessment asks whether authorities could access transferred data beyond what is necessary and proportionate. The importer’s experience and practices are strong evidence of real-world risk.
Can the importer refuse to answer questions about requests?
Some details may be legally restricted, but importers can usually describe their policy, confirm whether requests of your data type have been received and share transparency reports.
Do contract clauses stop government access?
No. They cannot override the law, but they can require notification, challenge and minimal disclosure, which improve outcomes and give you information.
What should we do if a request is received?
Follow your playbook: assess the legal position, consider challenge, limit disclosure, record the request, review the transfer and decide whether to suspend it.
Should we update the TIA after a request?
Yes. A request is a review trigger. Reassess the risk, the measures and the supplier’s response, and record the outcome.